Jpegoptim: Initial Project Proposal #12919
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
I am requesting permission to integrate jpegoptim into OSS-Fuzz. I believe that this project is a good candidate for OSS-Fuzz integration as it serves as a preeminent JPEG compression library used by many prominent projects such as NextCloud Server, ImageOptim, and Nikola.
For the sake of highlighting the library's importance and the risks posed by potential vulnerabilities within it, it is beneficial to consider NextCloud's usage of the library to handle image size optimization for storing user's data. Some potential risks include image corruption and loss of customer data and, as a worst -case-scenario, the exploitation of the JPEG parsing to achieve RCE on a public-network-facing file store.
Please see upstream approval for integration here